I plan to install Symantec Drive Encryption 10.3 (Previously PGP Whole Disk Encryption). What is the best practice for setting up the software?
(1) I see in Article:TECH202665 that Elcomsoft could read the encryption key if the hibernate file is not encrypted. Does this mean the Windows 7 operating system partition must be encrypted? If possible, I would like to avoid encrypting the Windows 7 system partition because that makes recovery difficult if the partition cannot boot up. My data is stored in a separate partition which will be encrypted.
(2) Does Symantec Drive Encryption (SDE) 10.3 make use of the TPM module in the laptop? How to enable it to use TPM?
(3) I read that using the SDE 10.3 recovery disk to decrypt the hard drive takes substantially longer because it is a 16-bit program. Is there a 32-bit recovery program to decrypt the hard drive?
(4) What is the recommended hard drive cloning program for image copy of an encrypted hard drive? I plan to clone the hard drive for backup purpose.
(5) I read that the single user license for SDE 10.3 includes one year essential support. Is this license perpetual even though I do not plan to renew the support after one year? Where can I renew the support service online?
Thank you.